180 incidents on record · 2026 Headlights Incident reports by Ellie Harris · Melbourne
10 new this week Library last updated 30 August 2026
← The incident library
HD-INC-165
Consumer AI · United States · 2024 · Impersonation of real people through user created personas

Character.AI removed reported chatbots impersonating deceased teenagers after families, lawyers and journalists notified it, and its terms of service already prohibited impersonating a real person

By Ellie Harris · Filed Reported October 2024 to March 2025

Alleged: Character Technologies, Inc. (Character.AI) developed or deployed the AI system implicated in this incident. Details are drawn from public reports; parties are presumed innocent of any wrongdoing not established by an official finding.

Character.AI removed reported chatbots impersonating deceased teenagers after families, lawyers and journalists notified it, and its terms of service already prohibited impersonating a real person

What happened

It was reported by Forbes on 2 October 2024 that a father received a Google Alert telling him somebody had created a chatbot on Character.AI using his murdered daughter’s yearbook photograph and name. It was reported that he contacted the company’s support team and received an automated response saying his complaint was being reviewed. A Character.AI spokesperson said the chatbot had been removed for violating its policies on impersonation.

It was then reported by the BBC on 30 October 2024 that the Telegraph had found characters imitating two British teenagers who had died. The BBC reported that the company’s terms of service ban impersonating any person, that the company said it moderated avatars proactively and in response to user reports, and that it deleted the chatbots after being alerted to them.

It was then reported by Futurism on 20 March 2025 that at least four publicly facing characters used the name and likeness of a teenager whose death is the subject of proceedings against the company, reachable through accounts listed as belonging to minors and easily searchable. Fortune reported the same day that lawyers for the teenager’s mother had found several more. The characters were deleted soon after Futurism approached the company, which said they violated its terms and that it was adding to its character blocklist.

The company’s own position, stated on its blog in October 2024, is that it conducts proactive detection and moderation of user created characters. In the three cases above, the reporting records removal following notification from a family member or a journalist, and in none of the sources reviewed did the company state that it had identified any of these characters itself. This entry does not treat that as a denial of proactive moderation, which the company asserts.

The Federal Trade Commission issued study orders under section 6(b) on 11 September 2025 to seven companies including Character Technologies, which is not an enforcement action. Character.AI announced on 29 October 2025 that it would remove open ended chat for users under 18, beginning 24 November. It was reported that Google and Character.AI agreed in principle in January 2026 to settle the lawsuits concerning teenage deaths, with no liability admitted. Proceedings filed by Kentucky and Pennsylvania in 2026 are allegations and have not been determined.

What an auditable version would have shown

In each of the three cases a prohibited character was found by someone outside the company: a father with a search alert on his dead daughter’s name, a newspaper that went looking, and a reporter and a family’s lawyers using the platform’s own search. The company says it also moderates proactively, but no published record shows what that moderation checked. A record written when a character is created, saying what was tested and what followed, would show how many prohibited personas were caught before publication and how many only after a report.

Where the gap was

It was reported that impersonating a person was already prohibited by the terms of service, and that characters using the names and photographs of deceased young people were nonetheless publicly reachable and, in the March 2025 case, searchable from accounts registered as belonging to minors. A PersonaGuard tests a persona against the operator’s declared identity rules at creation and again when it replies. A ConstraintGate runs the prohibition as a check before publication. A ConductRecord preserves what was tested and decided. None of these decides what a platform should allow; they make the prohibition demonstrable.

What governance should have looked like

The company’s position is that it moderates proactively and on user reports. The reporting reviewed here records three occasions on which the notification came from outside. Where users can create personas that others can reach, best practice would be to test a prohibition on impersonating real people before a character becomes reachable, to record the check so the organisation can state how much of its enforcement is proactive, and to have removal requests answered by people rather than automatically. Several of the matters above are live and untested.

Failure Pattern: user created personas prohibited by the platform’s own terms were publicly reachable, and in the three reported cases the company learned that a specific prohibited character existed through a family member, lawyers or journalists rather than through a documented proactive detection event.

Governance Principle: an organisation that lets users create personas should be able to test a new persona against its own prohibitions before it is published, and to show what it checked rather than relying on the people depicted to find it.

The reference implementation of PersonaGuard, ConstraintGate and ConductRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.

Sources

The mailing list

Fresh incident reports every week. One email to match.

We add new incidents to the library regularly, and send a single short email each week with what's new. The library stays free and open; this is just how you keep up with it.

No tracking. Unsubscribe in one click.

The record

An auditable system would have produced a signed, tamper-evident record the moment this happened: what the system did, the version that did it, the basis it acted on, and the action taken, and Character Technologies, Inc. (Character.AI) could have produced it on demand.

This is the record the system as deployed did not produce in a signed, auditable form.

What this teaches
Capture what happened when it happens
What the system did, the version that did it, the basis it acted on, and the action taken, recorded at the moment, not reconstructed after.
Sign it, so no one has to trust the record-keeper
A tamper-evident entry. Edit it later and the signature breaks. The record does not ask for the benefit of the doubt.
Make it verifiable by anyone
A court, a regulator, a customer's lawyer can check the record themselves, without taking the company, or us, at our word.

Headlights summarises publicly reported AI incidents. All summaries are independently written, attributed to their original sources, and intended for research and educational purposes. Allegations are identified as such until established through official findings.

This report is based on the sources listed above and reflects information available at the time of review; later developments may not be captured. Where a person is described as charged with or alleged to have done something, that allegation is unproven unless a conviction or a court or regulatory finding is stated. Headlights publishes journalism and commentary, not legal advice.

Want to write back?

Direct to my inbox.

ellie@useheadlights.com →